Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-0755


Rockwell Automation RSLogix 5000 7 through 20.01, and 21.0, does not properly implement password protection for .ACD files (aka project files), which allows local users to obtain sensitive information or modify data via unspecified vectors.


Published

2014-02-05T05:15:29.930

Last Modified

2025-09-19T19:15:35.777

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.3 (MEDIUM)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:C/I:C/A:N

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: NONE
Exploitability Score

3.4

Impact Score

9.2

Weaknesses
  • Type: Secondary
    CWE-522
  • Type: Secondary
    CWE-255

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rockwellautomation rslogix_5000_design_and_configuration_software 7.0 Yes
Application rockwellautomation rslogix_5000_design_and_configuration_software 18.0 Yes
Application rockwellautomation rslogix_5000_design_and_configuration_software 20.01 Yes
Application rockwellautomation rslogix_5000_design_and_configuration_software 21.0 Yes
Hardware rockwellautomation logix_5000_controller - No

References